Persistent 'Effluence' Backdoor Exploited in Widespread Atlassian Confluence Attacks

A stealthy backdoor named Effluence has been discovered by cybersecurity researchers, persisting despite patching Atlassian Confluence servers. The backdoor allows for lateral movement to other network resources and data exfiltration from Confluence, and can be accessed remotely without authentication. The attack chain involves exploiting critical vulnerabilities in Atlassian Confluence, including CVE-2023-22515 and CVE-2023-22518, which allow for unauthorized administrator account creation and complete loss of confidentiality, integrity, and availability. The attacker gains initial access through CVE-2023-22515 and embeds a web shell that grants persistent remote access to every web page on the server. The web shell's loader component acts as a normal Confluence plugin, while the payload component executes malicious actions. The backdoor is potentially applicable to other Atlassian products as well.
- Alert: 'Effluence' Backdoor Persists Despite Patching Atlassian Confluence Servers The Hacker News
- Hackers Exploiting Confluence Flaw to Deploy Ransomware GBHackers
- Patch now: Unauthenticated attackers target severe Atlassian Confluence vulnerability SiliconANGLE News
- Atlassian cranks up the threat meter to max for Confluence authorization flaw The Register
- Atlassian Confluence vulnerability under widespread attack TechTarget
Reading Insights
0
20
1 min
vs 2 min read
68%
376 → 121 words
Want the full story? Read the original article
Read on The Hacker News